A Deep Dive on the Recent Widespread DNS Hijacking

I’m excited about a proposed CAA extension (https://tools.ietf.org/html/draft-ietf-acme-caa-06) that would allow domain owners to restrict issuance to a particular ACME account and a particular validation method. This could provide stronger protection against most attacks short of a registry or registrar hijack. It’s implemented in Let’s Encrypt's staging environment, and I hope it’s able to move forward.